[Bug binutils/24829] readelf: multi interger overflow in readelf.c and dwarf.c

2019-08-22 Thread tfx_sec at hotmail dot com
https://sourceware.org/bugzilla/show_bug.cgi?id=24829 --- Comment #13 from tfx --- (In reply to Nick Clifton from comment #12) > Created attachment 11961 [details] > Another patch > > OK, in which case please could you try out this patch and let me know if it > fixes the bug ? > > Cheers > Ni

[Bug binutils/24829] readelf: multi interger overflow in readelf.c and dwarf.c

2019-08-21 Thread tfx_sec at hotmail dot com
https://sourceware.org/bugzilla/show_bug.cgi?id=24829 --- Comment #11 from tfx --- (In reply to Nick Clifton from comment #9) > (In reply to tfx from comment #7) > > > You can reproduce it use "readelf -w poc5" with ASAN. > > The crash output show as follow. > > Again I cannot reproduce this fa

[Bug binutils/24829] readelf: multi interger overflow in readelf.c and dwarf.c

2019-08-20 Thread tfx_sec at hotmail dot com
https://sourceware.org/bugzilla/show_bug.cgi?id=24829 tfx changed: What|Removed |Added Summary|readelf: interger overflow |readelf: multi interger |in a

[Bug binutils/24829] readelf: interger overflow in apply_relocations

2019-08-20 Thread tfx_sec at hotmail dot com
https://sourceware.org/bugzilla/show_bug.cgi?id=24829 --- Comment #8 from tfx --- Created attachment 11954 --> https://sourceware.org/bugzilla/attachment.cgi?id=11954&action=edit poc5 -- You are receiving this mail because: You are on the CC list for the bug. _

[Bug binutils/24829] readelf: interger overflow in apply_relocations

2019-08-20 Thread tfx_sec at hotmail dot com
https://sourceware.org/bugzilla/show_bug.cgi?id=24829 tfx changed: What|Removed |Added Status|RESOLVED|REOPENED Resolution|FIXED

[Bug binutils/24829] readelf: interger overflow in apply_relocations

2019-07-26 Thread tfx_sec at hotmail dot com
https://sourceware.org/bugzilla/show_bug.cgi?id=24829 --- Comment #2 from tfx --- Hi Nick, I tested this patch and it successfully fixed this problem. Thanks for your work. Cheers -- You are receiving this mail because: You are on the CC list for the bug.

[Bug binutils/24829] readelf: interger overflow in apply_relocations

2019-07-22 Thread tfx_sec at hotmail dot com
https://sourceware.org/bugzilla/show_bug.cgi?id=24829 tfx changed: What|Removed |Added CC||tfx_sec at hotmail dot com -- You are

[Bug binutils/24829] New: readelf: interger overflow in apply_relocations

2019-07-21 Thread tfx_sec at hotmail dot com
Component: binutils Assignee: unassigned at sourceware dot org Reporter: tfx_sec at hotmail dot com Target Milestone: --- Created attachment 11914 --> https://sourceware.org/bugzilla/attachment.cgi?id=11914&action=edit poc-interger-overflow Hi Nick, An interger o

[Bug binutils/24005] CVE-2018-20671 objdump integer overflow in load_specific_debug_section

2019-04-10 Thread tfx_sec at hotmail dot com
https://sourceware.org/bugzilla/show_bug.cgi?id=24005 tfx changed: What|Removed |Added Summary|objdump integer overflow in |CVE-2018-20671 objdump |load_

[Bug binutils/24360] Integer-Truncation / heap-overflow in objdump.c caused by commit-7a6e0d89

2019-03-19 Thread tfx_sec at hotmail dot com
https://sourceware.org/bugzilla/show_bug.cgi?id=24360 tfx changed: What|Removed |Added Summary|heap overflow in objdump.c |Integer-Truncation / |caused

[Bug binutils/24360] heap overflow in objdump.c caused by commit-7a6e0d89

2019-03-19 Thread tfx_sec at hotmail dot com
https://sourceware.org/bugzilla/show_bug.cgi?id=24360 tfx changed: What|Removed |Added CC||tfx_sec at hotmail dot com Host

[Bug binutils/24360] commit-7a6e0d89 cause PR24005 to reappear

2019-03-19 Thread tfx_sec at hotmail dot com
https://sourceware.org/bugzilla/show_bug.cgi?id=24360 --- Comment #1 from tfx --- Created attachment 11687 --> https://sourceware.org/bugzilla/attachment.cgi?id=11687&action=edit objdump -g heap overflow -- You are receiving this mail because: You are on the CC list for the bug.

[Bug binutils/24360] New: commit-7a6e0d89 cause PR24005 to reappear

2019-03-19 Thread tfx_sec at hotmail dot com
: binutils Assignee: unassigned at sourceware dot org Reporter: tfx_sec at hotmail dot com Target Milestone: --- -- You are receiving this mail because: You are on the CC list for the bug. ___ bug-binutils mailing list bug-binutils

[Bug binutils/24039] integer overflow in libiberty, heap overflow will be triggered

2019-01-04 Thread tfx_sec at hotmail dot com
https://sourceware.org/bugzilla/show_bug.cgi?id=24039 --- Comment #1 from mhsec --- I use latest binutils with debug info. crash output show as follow. binutils/nm-new -C POC = ==9029==ERROR: AddressSanitizer: heap-buffer-overflow

[Bug binutils/24005] objdump integer overflow in load_specific_debug_section

2019-01-04 Thread tfx_sec at hotmail dot com
https://sourceware.org/bugzilla/show_bug.cgi?id=24005 --- Comment #6 from mhsec --- It's 4GB, not 100GB. Of course I also think that this situation does not have to be considered. So my patch might work. -- You are receiving this mail because: You are on the CC list for the bug. ___

[Bug binutils/24005] objdump integer overflow in load_specific_debug_section

2019-01-04 Thread tfx_sec at hotmail dot com
https://sourceware.org/bugzilla/show_bug.cgi?id=24005 --- Comment #4 from mhsec --- (In reply to Nick Clifton from comment #3) > Hi mhsec, > > Thanks for reporting this problem. Unfortunately your proposed patch > will not work as it will prevent the tools from handling 64-bit binaries >

[Bug binutils/24039] integer overflow in libiberty, heap overflow will be triggered

2019-01-04 Thread tfx_sec at hotmail dot com
https://sourceware.org/bugzilla/show_bug.cgi?id=24039 mhsec changed: What|Removed |Added CC||tfx_sec at hotmail dot com -- You are